Назад
Company hidden
3 часа назад

GRC Program Architect

160 000 - 200 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Program Architect (FedRAMP/CMMC/SOC 2): Designing and implementing Onebrief's compliance framework and technical security controls for defense and government customers with an accent on RMF, federal compliance frameworks, audit readiness, and evidence systems. Focus on translating regulatory requirements into IAM, logging, encryption, vulnerability management, and infrastructure automation that withstand external reviews.

Location: United States, remote

Salary: $160,000–$200,000 per year, plus equity

Company

hirify.global builds collaboration and AI-powered workflow software for military planning and operational coordination, serving defense and government customers.

What you will do

  • Own the design and implementation of the GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
  • Build and manage policies, procedures, control environments, and evidence collection systems.
  • Implement technical security controls covering access management, logging, encryption, network security, and vulnerability management.
  • Partner with Product, Engineering, Infrastructure, and Corporate IT to make compliance controls operational and technically sound.
  • Manage customer security questionnaires, compliance inquiries, third-party audits, and assessor relationships.
  • Identify control gaps and improve audit and customer security review outcomes.

Requirements

  • 5+ years of experience in GRC, security engineering, or a combined compliance and technical security role.
  • Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks.
  • Hands-on experience implementing IAM, logging and monitoring, network segmentation, encryption, or similar technical controls.
  • Working knowledge of NIST 800-53 or NIST 800-171.
  • Experience managing third-party audits and assessor relationships.
  • Strong written English communication skills and the ability to translate regulatory requirements into clear technical guidance.

Nice to have

  • Experience in a startup or scaling company, or a background in military, defense, or government contracting.
  • CISSP, CISA, CRISC, AWS Solutions Architect, or another relevant certification.
  • Experience with GRC automation, infrastructure-as-code, scripting, GRC platforms, federal cloud security tooling, logging systems, or CI/CD pipelines.

Culture & Benefits

  • Remote-first organization with flexible work hours and unlimited PTO.
  • Health, dental, vision, and life insurance.
  • 401(k) plan with company match.
  • Eight weeks of parental leave at 100% regardless of state.
  • Annual company retreats and a $1,000 yearly home office budget.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →